Headlines covering AI doom abound. Leaders of the so-called frontier models are calling for unprecedented levels of regulation. Agents are running amok and attacking innocent bystanders.
At CYBR.SEC.CON 2026, much more sober and useful takes prevailed. Here are nine lessons I gathered from CYBR.SEC.CON 2026:
Full CYBR.SEC.CON. coverage:

1. Automation doesn't fix your process. It exposes it. Caleb Fogleman, who spoke on applying AI agents to security operations centers on behalf of Zscaler, warned against treating agents as a shortcut around workflows nobody had actually fixed before automating. "If you automate a bad process, you get a bad process, but faster," he said. The implication for a security operations director evaluating agent pilots: measure the underlying process first – an agent will not discover discipline your team doesn't already have instilled in their workflows.
2. Delegating a task to AI doesn't delegate the accountability. There’s been an abundance of agentic AI mishaps in recent weeks: OpenAI agents reaching production infrastructure at Hugging Face, an Anthropic misconfiguration nine days later, a comparable Meta incident six days after that. It’s all evidence that agent authority is scaling faster than the org charts meant to constrain it. Several speakers drove home the point that when people ask who is responsible for the actions of an autonomous agent, the answer can’t be the AI. Accountability needs to be named.
3. Traditional identity security was not built for agents spawning agents.
Morgan Reece, presenting research from TowerGuardian, located the gap in infrastructure most security teams treat as solved: OAuth, SPIFFE, and MCP verifying that a request is authentic. None of them verify that a chain of delegated sub-agents still carries the authority the original request granted. "Integrity is not authorization when you're talking with agents to agents," he said. Multi-hop agent delegation is a distinct challenge from single-agent identity, and most environments have yet to separate the two.
4. Strip the agentic AI framing from security incidents, and we have familiar root causes. Elizabeth Wharton, founder of Silver Key Strategies, worked through a run of 2026 incidents: hallucinated legal citations, a vibe-coded platform that leaked 1.5 million API authentication tokens, an agent that deleted a production database along with its backups and found the same failure underneath each: validation skipped, privilege unscoped, backups co-located with production. "AI may be novel, security failures aren't," she said.
None of those root causes require new tooling to fix. They require applying existing security tools.
5. The audit cycle is now too slow to matter. Dale Hoak, CISO at RegScale, made the compliance version of Wharton's argument: a control that's verified quarterly says nothing about whether it's still working today, and AI-accelerated exploitation can turn a single compromised machine into a hundred before the next assessment window opens. "Compliance cannot keep up with the speed of industry," he said. "It just can't."
Point-in-time compliance was always a lagging indicator. AI just made the lag expensive.
6. The more interesting risk isn't AI replacing decisions: it's AI shaping the inputs to them. Andy Ellis, CEO and principal at Duha Security, argued that human decision-making runs on cognitive shortcuts: filtered information, sticky mental frames that evolved for a much slower information environment. AI and algorithmic curation now sit upstream of those shortcuts, determining what a person sees before judgment even engages. "Frames tend to be sticky," he said. Governance conversations that stop at "can the model be wrong" miss this: the more consequential question is what the system chose to surface in the first place.
7. That makes attention itself part of the attack surface. Winn Schwartau, director of the Cognitive Security Institute, extended Ellis's point to organizational trust: whoever controls the information environment controls what an organization believes about itself, its leadership, and its risk. "They who control the technology control the narrative," he said. Security programs that model confidentiality, integrity, and availability but not perception are missing a threat AI has already made practical.
8. Even open-source governance now has an AI clause. Kelley Misata, president of the Open Information Security Foundation, said OISF wrote an AI contribution policy for Suricata this year addressing AI-assisted submissions and the conditions under which autonomous AI contributions get rejected outright. "Five years ago that sentence wouldn't have meant anything," she said. Security teams that treat open-source dependencies as a vulnerability-scanning problem are underestimating what's now a governance and provenance problem as well.
9. The pace AI is forcing is also straining the security pros managing it.
Joe Marshall's Human Incident Response Framework, introduced in his keynote, argues cybersecurity has built incident-response playbooks for compromised machines and never built an equivalent for the practitioners defending them. It’s essential the people working to keep systems safe in the agentic AI era stay healthy and mentally sharp and don’t get so depleted they can’t apply the risk mitigations needed.
None of these nine findings describe a new category of risk. They describe familiar cybersecurity gaps: process discipline, accountability, identity, validation, audit cadence, cognitive bias, dependency governance, and practitioner capacity running at a speed that no longer tolerates latency.
A CISO's agentic AI roadmap should be judged less by what the agents can do and more by how well these nine gaps are closed before the agents are given actual agency.
